IAC-25
Session Termination
Description
Automated mechanisms exist to log out users, both locally on the network and for remote sessions, at the end of the session or after an organization-defined period of inactivity.
Control Question
Does the organization use automated mechanisms to log out users, both locally on the network and for remote sessions, at the end of the session or after an organization-defined period of inactivity?
Control Metadata
Domain:
Identification & Authentication
Validation Cadence:
Quarterly
